Threats Tagged 'cve-'
View all threats tagged with 'cve-'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-79417 is a local denial-of-service vulnerability in Argus Monitor caused by an exposed IOCTL that allows unprivileged users to disable the x86 MONITOR and MWAIT instructions. Exploiting this vulnerability requires leveraging a time-of-check to time-of-use (TOCTOU) bug related to the SeLocateProcessImageName function. Successful exploitation triggers a HYPERVISOR_ERROR bugcheck, impacting Hyper-V and other kernel components that rely on these instructions. Join the discussion | Reddit NetSec | 09/29/2026, 00:00:00 UTC Added: 09/25/2026, 02:17:40 UTC |
0 CVE-2026-76460 is a critical vulnerability in Cisco Identity Services Engine (ISE) software versions 3.4.0 and 3.5.0. It involves insufficient authentication control on an API endpoint, allowing an unauthenticated remote attacker to bypass authentication. Exploiting this flaw could grant unauthorized access to the device's management interface, impacting confidentiality, integrity, and availability. Join the discussion | CVE Database V5 | 09/24/2026, 18:29:22 UTC Added: 09/16/2026, 20:47:45 UTC |
0 CVE-2026-25262 is a write-what-where vulnerability in the Qualcomm Sahara protocol experimentally confirmed on the Snapdragon 8 Gen 1 (SM8450) platform. It allows arbitrary writes to SRAM during the Sahara handshake, bypassing signature verification and partially bypassing Firehose loader authorization. The loader executes and responds to commands without authorization errors, but full UFS storage access has not yet been achieved. The vulnerability was previously known only on legacy 32-bit Qualcomm platforms but now affects modern 64-bit ARMv9 SoCs. No official patch or remediation guidance is currently available, and research is ongoing to achieve full Firehose initialization and understand TrustZone dependencies. Join the discussion | Reddit Cybersecurity | 09/22/2026, 09:45:18 UTC Added: 07/09/2026, 01:13:10 UTC |
A joint Tenable-SentinelOne analysis of 93 CVE-actor attribution pairs reveals that both state-sponsored actors and cybercriminals independently converge on the same edge infrastructure. Special thanks to SentinelOne® Incident Readiness & Response for their contributions to this publication. It is the shared attack surface where state-sponsored threat actors and financially motivated criminal groups independently converge — not the province of a single adversary category, and not exclusively a nation-state problem, despite two years of headlines about China-nexus actors targeting Ivanti, Fortinet, and Palo Alto Networks. The data here tells a different and much broader story. One focused on vendors vs CVEs. Key Takeaways Two independent observation systems, Tenable exposure telemetry across thousands of customer containers and SentinelOne DFIR casework across 66 CVEs, converge 79% on the same vendor attack surfaces despite minimal CVE-level overlap. Twelve CVEs in the combined dataset have confirmed multi-nexus attribution: state-sponsored and criminal actors independently exploiting the same vulnerability, across five nexus categories (China, Russia, DPRK, Iran, ransomware). The exposure picture is flatter than the headlines suggest: Fortinet, the vendor most associated with edge-device attacks in the press, sits mid-pack on container-grain exposure (25%) — well behind F5 (54%) and in a tight 10-point band with Check Point, Ivanti, and Citrix. 54% of customer environments running F5 products have at least one exposed, actively-exploited CVE; Citrix customers show the slowest remediation patterns at 461 days median time to patch. Remediation complexity, particularly of high priority CVEs, leads to a statistically significant 24-day remediation gap, leaving large windows of opportunity for attackers. The same product lines get hit again and again: Ivanti EPMM and Ivanti Connect Secure each show a newly exploited CVE roughly every 8.5 to 13 months. Leverage multiple defense-in-depth strategies: patch as quickly as possible, but also minimize the attack surface (feature-set minimization) and run endpoints in protect mode to better stop lateral movement from attacks that gain initial access. The convergence is the story Twelve CVEs in the combined dataset have confirmed multi-nexus attribution: state-sponsored and criminal actors independently exploiting the same vulnerability, across five nexus categories. Four examples illustrate the pattern: CVE Product Actors (Nexus) Significance CVE-2026-15409 SonicWall SMA1000 UTA0533 (unattributed) + INC Ransomware Espionage-to-ransomware succession on an active zero-day CVE-2023-42793 JetBrains TeamCity APT29 (Russia) + Lazarus (DPRK) Two state-sponsored actors from different nations on the same CVE CVE-2024-3400 PAN-OS GlobalProtect UTA0218 (China) + INC Ransomware China-nexus zero-day reused by ransomware operators CVE-2024-24919 Check Point Quantum PurpleHaze (China) + Fox Kitten (Iran) China and Iran independently exploiting the same gateway vulnerability The remaining eight confirmed multi-nexus CVEs span Fortinet, Citrix, Cisco, and Ivanti product lines. State-sponsored actors and ransomware operators are not operating in separate vulnerability ecosystems. They share the same entry points into the same products. The breadth of the convergence, not any single actor's activity, is the finding. That pattern holds across the full combined analysis. Three conclusions emerge: Vendor attack surfaces are the persistent exploitation target. The same eleven vendors (i.e., Fortinet, Citrix, Ivanti, Palo Alto Networks, Cisco, Juniper, VMware, Microsoft, Oracle, CrushFTP, and Meta's React framework ) appear in both observation systems at 79% convergence, and all seven edge-product vendors converge. Serial exploitation timing on Ivanti products shows the vulnerability-to-exploitation pipeline refreshing at 8.5 to 13-month intervals on the same product lines. This is structural, not episodic. Patch… Join the discussion | CVE Database V5 | 09/10/2026, 17:48:31 UTC Added: 07/14/2026, 20:03:48 UTC |
0 CVE-2026-86776 is a reported vulnerability affecting KeePass, referenced on a Reddit cybersecurity post linking to an external vulnerability database. No detailed technical information, affected versions, or patch status is provided in the available data. The vulnerability is rated medium severity but lacks further specifics or evidence of exploitation in the wild. Join the discussion | Reddit Cybersecurity | 09/09/2026, 13:16:17 UTC Added: 09/09/2026, 13:22:04 UTC |
CVE-2026-17106, known as CopyEscape, is a high-severity vulnerability in Docker's 'docker cp' command that allows a malicious container to write arbitrary files to the host filesystem. The flaw stems from a filesystem race condition during archive creation combined with unsafe symbolic link handling during extraction. This can lead to arbitrary file creation or overwriting on the host and potentially code execution depending on the privileges of the Docker CLI user. Docker has released official fixes in Docker Engine/CLI version 29.7.2 and later, Docker Desktop 4.86.0 and later, and Docker Sandboxes 0.38.0 and later. Join the discussion | Reddit Cybersecurity | 08/23/2026, 01:03:37 UTC Added: 08/11/2026, 15:56:04 UTC |
CVE-2026-6837 is a post-authentication OS command injection vulnerability in the export-cgi CGI program of Zyxel WAX650S firmware up to version 7.10(ABRM.4)C0. An attacker with administrator privileges could exploit this flaw to execute arbitrary OS commands on the device. The vulnerability has a high severity rating with a CVSS score of 7.2. No official patch or remediation guidance is currently provided by the vendor. Join the discussion | CVE Database V5 | 08/16/2026, 17:47:11 UTC Added: 08/04/2026, 12:56:07 UTC |
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. Join the discussion | CVE Database V5 | 08/11/2026, 17:05:15 UTC Added: 08/11/2026, 17:13:30 UTC |
0 CVE-2026-64638 is a high-severity pre-authentication reflected cross-site scripting (XSS) vulnerability in WordPress login pages that can lead to remote code execution (RCE) under specific conditions. The flaw allows attacker-controlled JavaScript to execute in the browser of a visitor after a failed login attempt. Exploitation requires a logged-in administrator to interact with an attacker-controlled page, potentially enabling PHP code execution on the server. The vulnerability affects default WordPress installations and was patched in WordPress 7.0.3 and backported to versions back through 4.7. Versions older than 4.7 remain vulnerable. WordPress recommends immediate updating, and automatic background updates should apply the patch automatically. No in-the-wild exploitation has been reported as of the advisory date. Join the discussion | Reddit Cybersecurity | 08/10/2026, 09:42:14 UTC Added: 08/07/2026, 14:26:03 UTC |
0 CVE-2026-17583 is a vulnerability in Thermo Fisher's Applied Biosystems human identification instruments where forensic DNA evidence files (.fsa and .hid) can be altered between creation and analysis without detection. Researchers demonstrated that these files could be modified in about 45 minutes to merge DNA profiles into a single file that appears unaltered since 2015. Thermo Fisher issued an update adding digital signatures to files created after the patch, but no retroactive validation exists for older files, and some end-of-life products do not receive updates. This leaves historical forensic DNA evidence files vulnerable to undetectable tampering. Join the discussion | Reddit Cybersecurity | 08/05/2026, 20:23:32 UTC Added: 08/04/2026, 16:56:02 UTC |
Showing 1 to 10 of 42 results